CVE-2005-2195: Medium severity Apple Darwin Streaming Server vulnerability
Published Jul 17, 2005
·Updated
Apple Darwin Streaming Server 5.5 and earlier allows remote attackers to cause a denial of service (application crash) via a URL with a filename containing a .cgi extension and an MS-DOS device name such as AUX, CON, PRN, COM1, or LPT1, a different vulnerability than CVE-2003-0421 and CVE-2003-0502.
Affected Software
1 affected component
Apple Darwin Streaming Server<=5.5
Remediation
Patch Available
Event History
Jul 17, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2195?
CVE-2005-2195 has been classified as a denial of service vulnerability.
2
How do I fix CVE-2005-2195?
To fix CVE-2005-2195, upgrade Apple Darwin Streaming Server to a version later than 5.5.
3
What versions are affected by CVE-2005-2195?
CVE-2005-2195 affects Apple Darwin Streaming Server versions 5.5 and earlier.
4
What kind of attack does CVE-2005-2195 facilitate?
CVE-2005-2195 facilitates a denial of service attack resulting in application crashes.
5
Can CVE-2005-2195 be exploited remotely?
Yes, CVE-2005-2195 can be exploited remotely by sending specially crafted URLs containing specific file names.